CVE-2026-0239
Chronosphere Chronocollector Information Disclosure Vulnerability
Severity
Medium 4.9
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.1th percentile
Discovered by
Vendor
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto
Description
An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.
Weakness: CWE-497
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Chronosphere | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Chronosphere Chronocollector
Credit
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
Vendor remediation
Version Suggested Solution Chronosphere Chronocollector Upgrade to v0.116.0 or later.